Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1057 Process Discovery |
GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| T1057 Process Discovery |
GroupKimsuky | Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1057 Process Discovery |
GroupHAFNIUM | HAFNIUM has used `tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupMuddyWater | MuddyWater has used malware to obtain a list of running processes on the system. |
| T1057 Process Discovery |
GroupGamaredon Group | Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer. |
| T1057 Process Discovery |
GroupTeamTNT | TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1057 Process Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1057 Process Discovery |
GroupAndariel | Andariel has used |
| T1057 Process Discovery |
GroupSidewinder | Sidewinder has used tools to identify running processes on the victim's machine. |
| T1057 Process Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1057 Process Discovery |
GroupRocke | Rocke can detect a running process's PID on the infected machine. |
| T1057 Process Discovery |
GroupUNC3886 | UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
| T1057 Process Discovery |
GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1057 Process Discovery |
GroupHigaisa | Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1057 Process Discovery |
GroupTropic Trooper | Tropic Trooper is capable of enumerating the running processes on the system using |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1057 Process Discovery |
GroupAPT1 | APT1 gathered a list of running processes on the system using |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1057 Process Discovery |
GroupStorm-0501 | Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1057 Process Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group lists all running processes. |
| T1057 Process Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers a list of running processes. |
| T1057 Process Discovery |
GroupChimera | Chimera has used |
| T1057 Process Discovery |
GroupMirrorFace | MirrorFace has used Tasklist on compromised hosts for discovery. |
| T1057 Process Discovery |
GroupMedusa Group | Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094. |
| T1057 Process Discovery |
GroupDarkhotel | Darkhotel malware can collect a list of running processes on a system. |
| T1057 Process Discovery |
GroupDeep Panda | Deep Panda uses the Microsoft Tasklist utility to list processes running on systems. |
| T1057 Process Discovery |
GroupWindshift | Windshift has used malware to enumerate active processes. |
| T1057 Process Discovery |
GroupToddyCat | ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| T1057 Process Discovery |
GroupAPT5 | APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| T1057 Process Discovery |
GroupWinnti Group | Winnti Group looked for a specific process running on infected servers. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1057 Process Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1057 Process Discovery |
GroupMolerats | Molerats actors obtained a list of active processes on the victim and sent them to C2 servers. |
| T1057 Process Discovery |
GroupInception | Inception has used a reconnaissance module to identify active processes and other associated loaded modules. |
| T1057 Process Discovery |
GroupPlay | Play has used the information stealer Grixba to check for a list of security processes. |
| T1057 Process Discovery |
GroupHEXANE | HEXANE has enumerated processes on targeted systems. |
| T1057 Process Discovery |
GroupMagic Hound | Magic Hound malware can list running processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.